2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-10150 | — | — | — | Dec 6, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-10149 | — | — | — | Dec 6, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-10148 | — | — | — | Dec 6, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-10147 | — | — | — | Dec 6, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-10146 | — | — | — | Dec 6, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-10145 | — | — | — | Dec 6, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2018-15332 | — | — | 0.3% | Dec 6, 2018 | The svpn component of the F5 BIG-IP APM client prior to version 7.1.7.2 for Linux and macOS runs as a privileged process... |
| CVE-2018-19907 | — | — | 1.7% | Dec 6, 2018 | A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may exe... |
| CVE-2018-19898 | — | — | 1.4% | Dec 6, 2018 | ThinkCMF X2.2.2 has SQL Injection via the method edit_post in ArticleController.class.php and is exploitable by normal a... |
| CVE-2018-19897 | — | — | 1.3% | Dec 6, 2018 | ThinkCMF X2.2.2 has SQL Injection via the function _listorders() in AdminbaseController.class.php and is exploitable wit... |
| CVE-2018-19896 | — | — | 1.3% | Dec 6, 2018 | ThinkCMF X2.2.2 has SQL Injection via the function delete() in SlideController.class.php and is exploitable with the man... |
| CVE-2018-19895 | — | — | 1.3% | Dec 6, 2018 | ThinkCMF X2.2.2 has SQL Injection via the function edit_post() in NavController.class.php and is exploitable with the ma... |
| CVE-2018-19894 | — | — | 1.3% | Dec 6, 2018 | ThinkCMF X2.2.2 has SQL Injection via the functions check() and delete() in CommentadminController.class.php and is expl... |
| CVE-2018-19893 | — | — | 1.1% | Dec 6, 2018 | SearchController.php in PbootCMS 1.2.1 has SQL injection via the index.php/Search/index.html query string. |
| CVE-2018-19892 | — | — | 1.5% | Dec 6, 2018 | DomainMOD through 4.11.01 has XSS via the admin/dw/add-server.php DisplayName, HostName, or UserName field. |
| CVE-2018-19891 | — | — | 0.9% | Dec 6, 2018 | An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Aud... |
| CVE-2018-19890 | — | — | 0.9% | Dec 6, 2018 | An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Aud... |
| CVE-2018-19889 | — | — | 0.9% | Dec 6, 2018 | An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Aud... |
| CVE-2018-19888 | — | — | 0.9% | Dec 6, 2018 | An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Aud... |
| CVE-2018-19887 | — | — | 0.9% | Dec 6, 2018 | An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Aud... |
| CVE-2018-19882 | — | — | 1.4% | Dec 6, 2018 | In Artifex MuPDF 1.14.0, the svg_run_image function in svg/svg-run.c allows remote attackers to cause a denial of servic... |
| CVE-2018-19881 | — | — | 1.6% | Dec 6, 2018 | In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by... |
| CVE-2018-19754 | — | — | 2.6% | Dec 5, 2018 | Tarantella Enterprise before 3.11 allows bypassing Access Control. |
| CVE-2018-19753 | — | — | 16.6% | Dec 5, 2018 | Tarantella Enterprise before 3.11 allows Directory Traversal. |
| CVE-2018-19650 | — | — | 0.6% | Dec 5, 2018 | Local attackers can trigger a stack-based buffer overflow on vulnerable installations of Antiy-AVL ATool security manage... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now